Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

211–220 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#211
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense.

I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi once, which simply didn't work.

PS. There may be working /secret-source/ alternatives, but I don't know why one should think Zoom /more/ untrustworthy than them.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#213
post #179

Earlier quoted context omitted.

>People spied. Did they? Which people? When? How?

All network traffic in the US should be seen as the opposite of innocent untill proven guilty: Unless you can prove otherwise, everything we know of surveillance tells us that of course everything and everyone was spied upon. I can't think of any reason the NSA and/or CIA should not have spied when they do so on everything else they can get their hands on.

Years ago, this attitude was seen as paranoid and bonkers. Then Snowden proved it true. Not only true, but barely scratching the surface. What's actually happening is beyond the wildest fever-dreams of the most extreme 90s crypto-punk ever.

Why are people still able to pretend otherwise without being laughed out of the room?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#214
post #19

Earlier quoted context omitted.

You're thinking of Tiktok.

From https://www.cnbc.com/2020/04/15/oracles-larry-ellison-calls-... : Along with is growth in users, Zoom has seen concerns spike about how it is protecting users’ privacy. The Senate advised members not to use the service, according to Ars Technica and the New York City Department of Education banned its use for remote learning. A group of state attorneys general are probing the company after one of the officials w…

So Ellison 'supports' Zoom, but as far as I can tell the connection with Trump is pure speculation.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#215
post #179

Earlier quoted context omitted.

>People spied. Did they? Which people? When? How?

All network traffic in the US should be seen as the opposite of innocent untill proven guilty: Unless you can prove otherwise, everything we know of surveillance tells us that of course everything and everyone was spied upon. I can't think of any reason the NSA and/or CIA should not have spied when they do so on everything else they can get their hands on.

They spy on network traffic outside the US, too.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#216
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Hi there! I'm in the video meeting space, and always looking to find that blend between usable and secure.

I'm curious - is there a video service out there you would recommend if you're conscious about security? Your third paragraph makes me think your opinion will be that no large company can be trusted, because they become a target for nation-state regulatory bodies.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#217
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

> [...] haven't built yourself, [...]

Reproducible builds remove this requirement.

https://en.wikipedia.org/wiki/Reproducible_builds

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#218
post #136

Earlier quoted context omitted.

I don't think I'd happily pay for Zoom, regardless of their encryption promises. I've personally struggled more with zoom call quality issues and hardware conflicts than I have with any other video conference provider.

Also anecdotally, I hear the opposite from every single person I know. Zoom has been the video conferencing system that works the best. Have you ever used Go2Meeting, WebEx, Teams? Constant struggles with those applications for me, my friends, and my co-workers.

In my experience, Google Meet is the one where no-one has problems. Zoom and Teams are the least reliable of the bunch.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#219
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

Cisco Webex is used in my workplace. We forbid anyone from installing Zoom over security concerns

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#220

Earlier quoted context omitted.

That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm. Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh? These are hard to quantify but they're not nothing.

Well, we can know. It was encrypted, but not E2EE, so the only person who could have spied was Zoom itself, and we know the how too - by the same mechanism it performs a video recording, for example. We just don't know if . But seeing as we've had zero reports of any real-world consequences that could only have come about by Zoom spying, combined with the fact that "spying on your customers" is anathema to your busin…

You definitely can’t apply Occam’s razor simply because you don’t have access to information.
Post reply on HN